Author

Articles by Andrew Pease

Elastic Security Labs Technology Lead, Elastic

Andrew Pease is the Elastic Security Labs Technology Lead. His team focuses on analyzing strategic, operational, and tactical threats. He was also the CEO and CIO of Perched, a professional services provider focusing on security consulting and training. Perched joined forces with Elastic in August 2019.

Andrew specializes in the People’s Republic of China (PRC) and the Democratic People's Republic of Korea (DPRK) economic espionage, intelligence, and counter-intelligence programs.

Andrew is the creator and maintainer of the Elastic Container Project.

Additionally, Andrew was a member of the Missouri Cyber Team (MOCYBER) within the Missouri National Guard. His team has developed techniques and methodologies for performing cyber hunting operations within Federal, State, and private industries. MOCYBER architected, engineered, and operationalized its own hunting platform known as ROCK (rocknsm.io) as well as its standalone operations technology stack, CAPES (capesstack.io). He retired from the Army National Guard after 20+ years as a Chief Warrant Officer Four, in 2021.

Videos

Bringing home the beacon (from Cobalt Strike)

We explore using Elastic to extract Cobalt Strike beacon payloads from memory and use open source tools to analyze and group threat activity clusters.